"-Synchronized-Data."

This commit is contained in:
CVE Team 2023-02-14 01:00:36 +00:00
parent f814443b98
commit a8e227ca0a
No known key found for this signature in database
GPG Key ID: E3252B3D49582C98

View File

@ -34,7 +34,7 @@
"description_data": [
{
"lang": "eng",
"value": "OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be triggered by an unauthenticated attacker in the default configuration. One third-party report states \"remote code execution is theoretically possible.\""
"value": "OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states \"remote code execution is theoretically possible.\""
}
]
},